Skip to content

Commit bbf3f75

Browse files
1 parent cc34b08 commit bbf3f75

File tree

1 file changed

+9
-0
lines changed

1 file changed

+9
-0
lines changed

_lolbas/Binaries/Winget.md

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -21,6 +21,13 @@ Commands:
2121
Privileges: User
2222
MitreID: T1105
2323
OperatingSystem: Windows 10, Windows 11
24+
- Command: winget.exe install --accept-package-agreements -s msstore {name or ID}
25+
Description: 'Download and install any software from the Microsoft Store using its name or Store ID, even if the Microsoft Store App itself is blocked on the machine, and even if AppLocker is active on the machine. For example, use "Sysinternals Suite" or `9p7knl5rwt25` for obtaining ProcDump, PsExec via the Sysinternals Suite. Note: a Microsoft account is required for this.'
26+
Usecase: Download and install software from Microsoft Store, even if Microsoft Store App is blocked, and AppLocker is activated on the machine
27+
Category: AWL Bypass
28+
Privileges: User
29+
MitreID: T1105
30+
OperatingSystem: Windows 10, Windows 11
2431
Full_Path:
2532
- Path: C:\Users\user\AppData\Local\Microsoft\WindowsApps\winget.exe
2633
Code_Sample:
@@ -33,8 +40,10 @@ Detection:
3340
Resources:
3441
- Link: https://saulpanders.github.io/2022/01/02/New-Year-New-LOLBAS.html
3542
- Link: https://docs.microsoft.com/en-us/windows/package-manager/winget/#production-recommended
43+
- Link: https://www.youtube.com/watch?v=zuL7x4Wltto
3644
Acknowledgement:
3745
- Person: Paul
3846
Handle: '@saulpanders'
3947
- Person: Konrad 'unrooted' Klawikowski
48+
- Person: Fredrik H. Brathen
4049
---

0 commit comments

Comments
 (0)